PT-2024-3927 · Libndp+9 · Libndp+9

Patrick Del Bello

·

Published

2024-05-31

·

Updated

2025-07-14

·

CVE-2024-5564

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: libndp (affected versions not specified)
Description: A flaw in libndp allows a local malicious user to cause a buffer overflow in NetworkManager. This issue is triggered by sending a malformed IPv6 router advertisement packet, as libndp does not correctly validate the route length information. The exploitation of this issue may allow an attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALSA-2024:4620
ALSA-2024:4636
AZL-42609
AZL-42625
BDU:2024-04337
CESA-2024_4620
CVE-2024-5564
DLA-3837-1
DSA-5713-1
INFSA-2024_4620
INFSA-2024_4636
MGASA-2024-0225
OESA-2024-1723
OPENSUSE-SU-2024:14112-1
OPENSUSE-SU-2024_2283-1
RHSA-2024:4618
RHSA-2024:4619
RHSA-2024:4620
RHSA-2024:4622
RHSA-2024:4636
RHSA-2024:4640
RHSA-2024:4641
RHSA-2024:4642
RHSA-2024:4643
RHSA-2024_4620
RHSA-2024_4636
RLSA-2024:4620
RLSA-2024:4636
ROSA-SA-2024-2493
SUSE-SU-2024:2283-1
SUSE-SU-2024:2541-1
SUSE-SU-2024_2283-1
SUSE-SU-2024_2541-1
SUSE-SU-2025:20088-1
USN-6830-1
USN-7248-1

Affected Products

Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Libndp